PT-2021-4363 · Moxa · Moxa Mxview Network Management

Noam Moshe

·

Published

2021-10-05

·

Updated

2022-10-25

·

CVE-2021-38454

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Moxa MXview Network Management software versions 3.x through 3.2.2
Description The issue is related to insufficient access control in the Moxa MXView network control software, which can be exploited by a remote attacker to bypass security restrictions using the MQTT protocol. A path traversal vulnerability may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries.
Recommendations For versions 3.x through 3.2.2, update to a version that addresses the path traversal vulnerability to prevent attackers from creating or overwriting critical files. As a temporary workaround, consider restricting access to the MQTT protocol to minimize the risk of exploitation. Avoid using the vulnerable version of the Moxa MXview Network Management software until a patch is available.

Fix

Improper Access Control

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2021-04993
CVE-2021-38454

Affected Products

Moxa Mxview Network Management